HIPAA Technical & Physical Safeguards 3 — Questions and Answers
Question 1: HIPAA's Transmission Security standard requires covered entities to guard against unauthorized access to ePHI during transmission. Which implementation specification is addressable under this standard?
- Unique User Identification
- Encryption of data in transit (Correct answer)
- Automatic Logoff
- Facility Access Controls
Correct answer: Encryption of data in transit
Encryption of ePHI in transit is an addressable implementation specification under the Transmission Security standard; covered entities must implement it or document why it is not reasonable.
Question 2: Under the Device and Media Controls standard, the 'accountability' implementation specification requires covered entities to maintain records of:
- All ePHI access by workforce members
- The movements of hardware and electronic media (Correct answer)
- Software licenses for systems storing ePHI
- Annual security risk assessments
Correct answer: The movements of hardware and electronic media
The accountability specification requires a record of the movements of hardware and electronic media and the person responsible for those movements.
Question 3: What does the 'unique user identification' implementation specification under HIPAA's Access Control standard require?
- Each user must use a unique name or number to identify themselves (Correct answer)
- Each facility must have a unique identifier registered with HHS
- All ePHI must include a patient's unique identifier
- Passwords must be unique and changed every 90 days
Correct answer: Each user must use a unique name or number to identify themselves
Unique user identification requires assigning each user a unique name or number so system activity can be traced to that specific individual.
Question 4: A covered entity experiences a power outage affecting its data center. Which Physical Safeguard implementation specification addresses restoring access to ePHI during emergencies?
- Workstation Security
- Contingency Operations (Correct answer)
- Maintenance Records
- Accountability
Correct answer: Contingency Operations
Contingency Operations procedures establish how to restore access to data protected by access controls in the event of a disaster or emergency.
Question 5: Under HIPAA technical safeguards, which standard specifically addresses ensuring that ePHI transmitted over an electronic network has not been improperly modified?
- Access Control
- Audit Controls
- Integrity (Correct answer)
- Person or Entity Authentication
Correct answer: Integrity
The Integrity standard requires policies and procedures to protect ePHI from improper alteration or destruction, including during transmission.
Question 6: A practice's policy requires that all laptops used off-site must have full-disk encryption enabled. This addresses which category of HIPAA safeguard?
- Administrative Safeguards
- Physical Safeguards — Device and Media Controls (Correct answer)
- Technical Safeguards — Access Control
- Technical Safeguards — Transmission Security
Correct answer: Physical Safeguards — Device and Media Controls
Full-disk encryption on portable devices is a control under Device and Media Controls, which governs hardware and media that house ePHI.
Question 7: What is the primary goal of the 'Person or Entity Authentication' standard under HIPAA's Technical Safeguards?
- To encrypt all ePHI at rest
- To verify that a person or entity seeking access is who they claim to be (Correct answer)
- To log all failed login attempts
- To require multi-factor authentication for all systems
Correct answer: To verify that a person or entity seeking access is who they claim to be
Person or Entity Authentication requires implementing procedures to verify the identity of anyone seeking access to ePHI.
HIPAA's Transmission Security standard requires covered entities to guard against unauthorized access to ePHI during transmission.
Which implementation specification is addressable under this standard?